Sample Header Ad - 728x90

hash:net,iface ipset equivalent nftables set

1 vote
0 answers
84 views
I'm trying to move an ipset to an nftables set:
[my-host]# ipset-translate restore <<< 'create foonet_iface hash:net,iface family inet hashsize 1024 maxelem 65536'
add table inet global
add set inet global foonet_iface { type ipv4_addr . ifname; size 65536; flags interval; }
[my-host]# ipset-translate restore <<< 'create foonet_iface hash:net,iface family inet hashsize 1024 maxelem 65536' | xargs -d '\n' -n1 nft
Error: Could not process rule: Operation not supported
add set inet global foonet_iface { type ipv4_addr . ifname; size 65536; flags interval; }
^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
[my-host]#
The equivalent seems to be a set of type ipv4_addr . ifname with the interval flag. But I don't seem to be able to create it. Kernel version is 5.4
Asked by Philippe (569 rep)
Jul 10, 2024, 08:02 AM